Patient Notice

Patient Notice Effective March 31, 2025

 

iRhythm Technologies, Inc. ("iRhythm™"), care about your confidentiality and privacy rights in accordance with applicable laws. Please read this patient notice carefully before using your Zio® Monitor cardiac monitor or returning it to iRhythm. By using the Zio® Monitor to us, you acknowledge that you have read and understood this patient notice (as contained in the Zio booklet).

 

1. CONFIDENTIALITY AND CONSENT

Your doctor has prescribed the Zio service for you. iRhythm provides the Zio service, which includes long-term heart monitoring and evaluation. Your doctor will, with your consent, start the Zio service by providing the adhesive monitoring device, which will be placed on your chest. This device will collect your heart rhythm data. Your doctor will collect personal information such as your name, address and date of birth to safely identify your resulting heart rhythm report and provide that information to iRhythm on iRhythm’s physician portal. Your heart rhythm data will be sent to iRhythm when you return the Zio patch by post.

 

iRhythm receives and processes your personal information to help create a report of the findings. Only iRhythm, your doctor and hospital will have access to this report for the purpose of supporting your direct care. iRhythm may also study your heart rhythm data for the purposes described below.

 

2. DATA PROTECTION

Here we explain how iRhythm collects and uses your personal information and heart rhythm data during and after your use of the Zio service.

How will iRhythm use personal information it receives about you?

iRhythm may use your personal information for the following purposes:

• Provision of diagnostic services.

• Improving the quality of diagnostic services including our use of AI to improve diagnostic accuracy and patient safety.

• Statistical analysis and reporting.

• Clinical standards and reporting.

• Patient safety and protection.

• Assessing, responding to and reporting on patient enquiries, experience, complaints and feedback.

 

Our use of Artificial Intelligence

Our use of Artificial Intelligence helps eliminate the risks of error associated with a purely human review of heart rhythm data. Our diagnostic systems do not use solely automated decision making but support, rather than replace, clinician review. This is

complete by drawing upon derived understanding from analyzing and comparing thousands of different heart rhythm patterns. This machine learning helps our software to recognize and flag anomalies for closer inspection by our clinicians, thereby enabling more efficient heart rhythm analysis for faster, more reliable diagnostic outcomes.

We apply rigorous measures to ensure data we use for this purpose is safeguarded in accordance with applicable laws. Heart rhythm data and associated clinical markers are extracted and processed in a separate environment from your personal information. The purpose of this processing is to better inform at a system level, the understanding of different diagnostic models rather decisions relating to you.

 

Data sharing

We may share your information in the following circumstances:

1. Within iRhythm when needed to support our processing of your personal data.

2. iRhythm may provide personal information to third parties including our vendors, partners and service providers (e.g. cloud service providers) who perform services on our behalf. These providers have limited access to your personal information only to the extent necessary to perform these support tasks on our behalf and subject to the same confidentiality and security safeguards as those applied by iRhythm.

 

In certain situations, we may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements

 

We are responsible and remain liable for the processing of personal information we receive, including where this involves an International Transfer of personal information or if we subsequently transfer to a third party acting as an agent on our behalf.

 

International Transfers

In accordance with data protection law(s), iRhythm will transfer only necessary personal information to its independent diagnostic testing facility in the United States in accordance with applicable laws and regulations.

 

iRhythm’s privacy practices described in this notice comply with the APEC Cross Border Privacy Rules System. The APEC CBPR system provides a framework for organizations to ensure protection of personal information transferred among participating APEC economies. More information about the APEC framework can be found here.

 

How long will your information be used for?

We retain personal information for the length of your use of the Zio service and as necessary to meet our contractual obligations, to identify issues or to resolve legal proceedings. We may also retain aggregate information beyond this time for research purposes and to help us develop and improve our services.

 

Your rights in connection with personal information

You may request to verify and edit any of your personal information by contacting iRhythm’s Privacy Official via the contact information listed below.

 

Where the processing of your personal information by us is based on consent, you have the right to withdraw that consent by contacting your doctor or hospital. The possible consequences of this will be explained to you and could include delays in diagnosis, care or treatment that the Zio service supports.

 

Contacting iRhythm and resolving disputes about your information

You can contact iRhythm about your rights or with any questions about this patient notice by contacting the iRhythm via email at supportJP@irhythmtech.com or by calling toll-free phone number: 050-3625-8223.

If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.

 

Complaint to Your Personal Information Protection Commission

If your request or enquiry is not resolved to your satisfaction, you may approach your supervisory authority for data protection concerns: Personal Information Protection Commission http://www.ppc.go.jp

 

Updates to the Patient Notice

We may update this Patient Notice to reflect changes to our information practices. If we make any material changes we will notify you by email (sent to the e-mail address specified in your account) or by means of a notice on this website prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.

 

iRhythm Technologies Inc.

699 8th Street

Suite 600

San Francisco CA 94103

TRUSTe

WEB0187.01